To manually configure the audit policies needed to run Syscheck’s whodata mode, it is necessary
to activate the capture of successful events. You can do it from the Local Group Policy Editor using the following command: